Act
archived
Russian UAT-11795 trojanizes WebEx/Zoom apps to deploy Starland RAT
- Engineer — Plan: Trojanized installers for widely-deployed conferencing tools represent a real supply-chain-adjacent risk; no exploitation signals provided. Audit all WebEx/Zoom deployments to confirm they originate from official signed packages or MDM-managed distribution, and block unapproved installer sources.
- SOC/IR — Act: Active campaign using trojanized enterprise conferencing apps to drop a credential-stealing RAT; hunt for unsigned or anomalous WebEx/Zoom process trees since the compromise starts before any patch can help. Pull Starland RAT IOCs from the BleepingComputer article and sweep endpoint logs for suspicious child processes or C2 traffic from conferencing app directories.
- Leader — Learn: Financially motivated Russian actor targeting enterprise collaboration tools is worth noting as sector-level context, but with no confirmed breach at a shared vendor and no enrichment signals, this does not yet require leadership action or customer communication.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.